Blockchain AcademicsBlockchain Academics
Coldcard Attacker Moves $7.7M in Stolen Bitcoin Through THORChain and CoinJoin

Coldcard Attacker Moves $7.7M in Stolen Bitcoin Through THORChain and CoinJoin

The attacker behind the third wave of Coldcard hardware wallet compromises has shifted approximately 45% of stolen funds, routing $7.7 million through THORChain and CoinJoin. Galaxy reports 82% of all Bitcoin stolen across Coldcard attacks remains in original addresses.

Julie "Mooncat" WolfEdited by Wael RajabSeptember 7, 20263 min read
Share

Coldcard Attacker Moves $7.7M in Stolen Bitcoin Through THORChain and CoinJoin

$7.7 million in stolen Bitcoin started moving this week. The attacker behind the third wave of Coldcard hardware wallet compromises has shifted approximately 45% of the funds taken in that wave, routing the coins through THORChain and CoinJoin in what blockchain analysts describe as an active laundering operation.

According to on-chain analysis from Galaxy, 82% of all Bitcoin stolen across every Coldcard attack wave remains parked at the original addresses. That means 18% has been moved so far, with this latest transfer representing the most significant single laundering push yet observed across the series of breaches.

The routing choice is deliberate. THORChain is a decentralized cross-chain exchange that allows users to swap assets across blockchains without a centralized intermediary, making it a common tool for obscuring fund origins. CoinJoin is a Bitcoin-native privacy technique that pools multiple transactions together, breaking the direct on-chain link between a sender and recipient. Used in sequence, the two methods create meaningful analytical friction. The catch: neither is invisible. Blockchain analysis firms can and do trace THORChain swaps and CoinJoin clusters with varying degrees of confidence, and the fact that Galaxy has already characterized these movements publicly suggests the trail is not cold.

Galaxy said 82% of Bitcoin stolen across all Coldcard attacks remains in the original addresses, with 18% moved in apparent laundering.

Galaxy, blockchain analysis firm

The 82% figure sitting unmoved warrants careful reading. It could indicate caution, a deliberate drip strategy to avoid triggering exchange compliance flags, or simply that the attacker has not yet found a clean exit for the bulk of the haul. Large sudden movements of stolen Bitcoin tend to attract immediate attention from exchanges and analytics firms, so staged laundering across multiple waves is a rational approach from the attacker's perspective.

Coldcard is a Bitcoin-only hardware wallet widely regarded as one of the more security-hardened options available to self-custody users. Multiple attack waves against the same product line is an unusual pattern. Hardware wallet compromises typically stem from supply chain tampering, firmware vulnerabilities, or user-side operational security failures rather than fundamental design flaws, and it is not yet clear which vector accounts for these breaches. Whether this series reflects a systemic issue or exploitation of a specific firmware version or configuration remains an open question that Coinkite, the company behind Coldcard, will need to answer definitively.

In the broader context of crypto theft, $7.7 million is a relatively contained figure. The Ronin Network breach in 2022 saw $625 million extracted in a single event. But the Coldcard incidents carry a different kind of reputational weight: hardware wallets are the last line of defense for self-custody holders, and repeated successful attacks against the same product erode the foundational premise that cold storage is categorically safer than exchange custody. That perception risk extends beyond any single dollar figure.

Fund recovery in hardware wallet compromises is historically rare without law enforcement involvement and cooperation from centralized exchanges at the off-ramp. With the attacker now actively moving funds through decentralized infrastructure, the window for a clean seizure narrows with each transaction.

Discussion

Loading comments...